Are Your Services Compliant?

Item request has been placed! ×
Item request cannot be made. ×
loading   Processing Request
  • Additional Information
    • Subject Terms:
    • Abstract:
      This article comments on new challenges being posed by software as a service (SaaS) for companies in the U.S. facing regulatory requirements, as of May 2006. Surprisingly, with all the discussion around SaaS in the enterprise, the issue of SaaS supporting the need of public companies for Sarbanes-Oxley (SOX) compliance has yet to be discussed. However, it is difficult to nail down what it means for as SaaS company to be SOX-compliant for the benefit of its customers. Under Section 404 of SOX, most companies are required to have a Statement on Auditing Standards No. 70 (SAS 70) report from their service providers to evaluate controls, operations, datacenters, security, backup and system availability. If you are considering an SaaS solution for a department, a division, or the whole company, due diligence requires that you make sure the online solution provider you plan to use has SAS 70 or similar certification.